Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 1 | /* |
| 2 | * This is a module which is used for rejecting packets. |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 3 | */ |
| 4 | |
| 5 | /* (C) 1999-2001 Paul `Rusty' Russell |
| 6 | * (C) 2002-2004 Netfilter Core Team <coreteam@netfilter.org> |
| 7 | * |
| 8 | * This program is free software; you can redistribute it and/or modify |
| 9 | * it under the terms of the GNU General Public License version 2 as |
| 10 | * published by the Free Software Foundation. |
| 11 | */ |
| 12 | |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 13 | #include <linux/module.h> |
| 14 | #include <linux/skbuff.h> |
Tejun Heo | 5a0e3ad | 2010-03-24 17:04:11 +0900 | [diff] [blame^] | 15 | #include <linux/slab.h> |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 16 | #include <linux/ip.h> |
| 17 | #include <linux/udp.h> |
| 18 | #include <linux/icmp.h> |
| 19 | #include <net/icmp.h> |
| 20 | #include <net/ip.h> |
| 21 | #include <net/tcp.h> |
| 22 | #include <net/route.h> |
| 23 | #include <net/dst.h> |
Jan Engelhardt | 6709dbb | 2007-02-07 15:11:19 -0800 | [diff] [blame] | 24 | #include <linux/netfilter/x_tables.h> |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 25 | #include <linux/netfilter_ipv4/ip_tables.h> |
| 26 | #include <linux/netfilter_ipv4/ipt_REJECT.h> |
| 27 | #ifdef CONFIG_BRIDGE_NETFILTER |
| 28 | #include <linux/netfilter_bridge.h> |
| 29 | #endif |
| 30 | |
| 31 | MODULE_LICENSE("GPL"); |
| 32 | MODULE_AUTHOR("Netfilter Core Team <coreteam@netfilter.org>"); |
Jan Engelhardt | 2ae15b6 | 2008-01-14 23:42:28 -0800 | [diff] [blame] | 33 | MODULE_DESCRIPTION("Xtables: packet \"rejection\" target for IPv4"); |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 34 | |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 35 | /* Send RST reply */ |
| 36 | static void send_reset(struct sk_buff *oldskb, int hook) |
| 37 | { |
| 38 | struct sk_buff *nskb; |
Jan Engelhardt | 3cf93c9 | 2008-04-14 09:56:05 +0200 | [diff] [blame] | 39 | const struct iphdr *oiph; |
| 40 | struct iphdr *niph; |
| 41 | const struct tcphdr *oth; |
| 42 | struct tcphdr _otcph, *tcph; |
Patrick McHardy | 9d02002 | 2006-10-02 16:12:20 -0700 | [diff] [blame] | 43 | unsigned int addr_type; |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 44 | |
| 45 | /* IP header checks: fragment. */ |
Arnaldo Carvalho de Melo | eddc9ec | 2007-04-20 22:47:35 -0700 | [diff] [blame] | 46 | if (ip_hdr(oldskb)->frag_off & htons(IP_OFFSET)) |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 47 | return; |
| 48 | |
Arnaldo Carvalho de Melo | c9bdd4b | 2007-03-12 20:09:15 -0300 | [diff] [blame] | 49 | oth = skb_header_pointer(oldskb, ip_hdrlen(oldskb), |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 50 | sizeof(_otcph), &_otcph); |
| 51 | if (oth == NULL) |
YOSHIFUJI Hideaki | e905a9e | 2007-02-09 23:24:47 +0900 | [diff] [blame] | 52 | return; |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 53 | |
| 54 | /* No RST for RST. */ |
| 55 | if (oth->rst) |
| 56 | return; |
| 57 | |
Patrick McHardy | 6150bac | 2005-06-21 14:03:46 -0700 | [diff] [blame] | 58 | /* Check checksum */ |
Arnaldo Carvalho de Melo | c9bdd4b | 2007-03-12 20:09:15 -0300 | [diff] [blame] | 59 | if (nf_ip_checksum(oldskb, hook, ip_hdrlen(oldskb), IPPROTO_TCP)) |
Patrick McHardy | 6150bac | 2005-06-21 14:03:46 -0700 | [diff] [blame] | 60 | return; |
Denys Vlasenko | 9ba99b0 | 2008-01-14 23:44:26 -0800 | [diff] [blame] | 61 | oiph = ip_hdr(oldskb); |
Patrick McHardy | 6150bac | 2005-06-21 14:03:46 -0700 | [diff] [blame] | 62 | |
Denys Vlasenko | 9ba99b0 | 2008-01-14 23:44:26 -0800 | [diff] [blame] | 63 | nskb = alloc_skb(sizeof(struct iphdr) + sizeof(struct tcphdr) + |
| 64 | LL_MAX_HEADER, GFP_ATOMIC); |
Patrick McHardy | 9d02002 | 2006-10-02 16:12:20 -0700 | [diff] [blame] | 65 | if (!nskb) |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 66 | return; |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 67 | |
Denys Vlasenko | 9ba99b0 | 2008-01-14 23:44:26 -0800 | [diff] [blame] | 68 | skb_reserve(nskb, LL_MAX_HEADER); |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 69 | |
Denys Vlasenko | 9ba99b0 | 2008-01-14 23:44:26 -0800 | [diff] [blame] | 70 | skb_reset_network_header(nskb); |
| 71 | niph = (struct iphdr *)skb_put(nskb, sizeof(struct iphdr)); |
| 72 | niph->version = 4; |
| 73 | niph->ihl = sizeof(struct iphdr) / 4; |
| 74 | niph->tos = 0; |
| 75 | niph->id = 0; |
| 76 | niph->frag_off = htons(IP_DF); |
| 77 | niph->protocol = IPPROTO_TCP; |
| 78 | niph->check = 0; |
| 79 | niph->saddr = oiph->daddr; |
| 80 | niph->daddr = oiph->saddr; |
Herbert Xu | bbf4a6b | 2007-02-13 12:32:58 -0800 | [diff] [blame] | 81 | |
Denys Vlasenko | 9ba99b0 | 2008-01-14 23:44:26 -0800 | [diff] [blame] | 82 | tcph = (struct tcphdr *)skb_put(nskb, sizeof(struct tcphdr)); |
| 83 | memset(tcph, 0, sizeof(*tcph)); |
| 84 | tcph->source = oth->dest; |
| 85 | tcph->dest = oth->source; |
| 86 | tcph->doff = sizeof(struct tcphdr) / 4; |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 87 | |
Denys Vlasenko | 9ba99b0 | 2008-01-14 23:44:26 -0800 | [diff] [blame] | 88 | if (oth->ack) |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 89 | tcph->seq = oth->ack_seq; |
Denys Vlasenko | 9ba99b0 | 2008-01-14 23:44:26 -0800 | [diff] [blame] | 90 | else { |
Arnaldo Carvalho de Melo | c9bdd4b | 2007-03-12 20:09:15 -0300 | [diff] [blame] | 91 | tcph->ack_seq = htonl(ntohl(oth->seq) + oth->syn + oth->fin + |
| 92 | oldskb->len - ip_hdrlen(oldskb) - |
| 93 | (oth->doff << 2)); |
Denys Vlasenko | 9ba99b0 | 2008-01-14 23:44:26 -0800 | [diff] [blame] | 94 | tcph->ack = 1; |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 95 | } |
| 96 | |
Denys Vlasenko | 9ba99b0 | 2008-01-14 23:44:26 -0800 | [diff] [blame] | 97 | tcph->rst = 1; |
| 98 | tcph->check = tcp_v4_check(sizeof(struct tcphdr), |
| 99 | niph->saddr, niph->daddr, |
| 100 | csum_partial(tcph, |
| 101 | sizeof(struct tcphdr), 0)); |
Patrick McHardy | 9d02002 | 2006-10-02 16:12:20 -0700 | [diff] [blame] | 102 | |
| 103 | addr_type = RTN_UNSPEC; |
Patrick McHardy | 6e23ae2 | 2007-11-19 18:53:30 -0800 | [diff] [blame] | 104 | if (hook != NF_INET_FORWARD |
Patrick McHardy | 9d02002 | 2006-10-02 16:12:20 -0700 | [diff] [blame] | 105 | #ifdef CONFIG_BRIDGE_NETFILTER |
| 106 | || (nskb->nf_bridge && nskb->nf_bridge->mask & BRNF_BRIDGED) |
| 107 | #endif |
| 108 | ) |
| 109 | addr_type = RTN_LOCAL; |
| 110 | |
Denys Vlasenko | 9ba99b0 | 2008-01-14 23:44:26 -0800 | [diff] [blame] | 111 | /* ip_route_me_harder expects skb->dst to be set */ |
Eric Dumazet | adf3090 | 2009-06-02 05:19:30 +0000 | [diff] [blame] | 112 | skb_dst_set(nskb, dst_clone(skb_dst(oldskb))); |
Denys Vlasenko | 9ba99b0 | 2008-01-14 23:44:26 -0800 | [diff] [blame] | 113 | |
Herbert Xu | 3db05fea | 2007-10-15 00:53:15 -0700 | [diff] [blame] | 114 | if (ip_route_me_harder(nskb, addr_type)) |
Patrick McHardy | 9d02002 | 2006-10-02 16:12:20 -0700 | [diff] [blame] | 115 | goto free_nskb; |
| 116 | |
Eric Dumazet | adf3090 | 2009-06-02 05:19:30 +0000 | [diff] [blame] | 117 | niph->ttl = dst_metric(skb_dst(nskb), RTAX_HOPLIMIT); |
Patrick McHardy | 4cf411d | 2006-08-05 00:58:33 -0700 | [diff] [blame] | 118 | nskb->ip_summed = CHECKSUM_NONE; |
Patrick McHardy | af443b6 | 2006-11-28 20:10:21 -0800 | [diff] [blame] | 119 | |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 120 | /* "Never happens" */ |
Eric Dumazet | adf3090 | 2009-06-02 05:19:30 +0000 | [diff] [blame] | 121 | if (nskb->len > dst_mtu(skb_dst(nskb))) |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 122 | goto free_nskb; |
| 123 | |
| 124 | nf_ct_attach(nskb, oldskb); |
| 125 | |
Herbert Xu | c439cb2 | 2008-01-11 19:14:00 -0800 | [diff] [blame] | 126 | ip_local_out(nskb); |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 127 | return; |
| 128 | |
| 129 | free_nskb: |
| 130 | kfree_skb(nskb); |
| 131 | } |
| 132 | |
| 133 | static inline void send_unreach(struct sk_buff *skb_in, int code) |
| 134 | { |
| 135 | icmp_send(skb_in, ICMP_DEST_UNREACH, code, 0); |
YOSHIFUJI Hideaki | e905a9e | 2007-02-09 23:24:47 +0900 | [diff] [blame] | 136 | } |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 137 | |
Jan Engelhardt | d3c5ee6 | 2007-12-04 23:24:03 -0800 | [diff] [blame] | 138 | static unsigned int |
Jan Engelhardt | 7eb3558 | 2008-10-08 11:35:19 +0200 | [diff] [blame] | 139 | reject_tg(struct sk_buff *skb, const struct xt_target_param *par) |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 140 | { |
Jan Engelhardt | 7eb3558 | 2008-10-08 11:35:19 +0200 | [diff] [blame] | 141 | const struct ipt_reject_info *reject = par->targinfo; |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 142 | |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 143 | /* WARNING: This code causes reentry within iptables. |
| 144 | This means that the iptables jump stack is now crap. We |
| 145 | must return an absolute verdict. --RR */ |
YOSHIFUJI Hideaki | e905a9e | 2007-02-09 23:24:47 +0900 | [diff] [blame] | 146 | switch (reject->with) { |
| 147 | case IPT_ICMP_NET_UNREACHABLE: |
Herbert Xu | 3db05fea | 2007-10-15 00:53:15 -0700 | [diff] [blame] | 148 | send_unreach(skb, ICMP_NET_UNREACH); |
YOSHIFUJI Hideaki | e905a9e | 2007-02-09 23:24:47 +0900 | [diff] [blame] | 149 | break; |
| 150 | case IPT_ICMP_HOST_UNREACHABLE: |
Herbert Xu | 3db05fea | 2007-10-15 00:53:15 -0700 | [diff] [blame] | 151 | send_unreach(skb, ICMP_HOST_UNREACH); |
YOSHIFUJI Hideaki | e905a9e | 2007-02-09 23:24:47 +0900 | [diff] [blame] | 152 | break; |
| 153 | case IPT_ICMP_PROT_UNREACHABLE: |
Herbert Xu | 3db05fea | 2007-10-15 00:53:15 -0700 | [diff] [blame] | 154 | send_unreach(skb, ICMP_PROT_UNREACH); |
YOSHIFUJI Hideaki | e905a9e | 2007-02-09 23:24:47 +0900 | [diff] [blame] | 155 | break; |
| 156 | case IPT_ICMP_PORT_UNREACHABLE: |
Herbert Xu | 3db05fea | 2007-10-15 00:53:15 -0700 | [diff] [blame] | 157 | send_unreach(skb, ICMP_PORT_UNREACH); |
YOSHIFUJI Hideaki | e905a9e | 2007-02-09 23:24:47 +0900 | [diff] [blame] | 158 | break; |
| 159 | case IPT_ICMP_NET_PROHIBITED: |
Herbert Xu | 3db05fea | 2007-10-15 00:53:15 -0700 | [diff] [blame] | 160 | send_unreach(skb, ICMP_NET_ANO); |
YOSHIFUJI Hideaki | e905a9e | 2007-02-09 23:24:47 +0900 | [diff] [blame] | 161 | break; |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 162 | case IPT_ICMP_HOST_PROHIBITED: |
Herbert Xu | 3db05fea | 2007-10-15 00:53:15 -0700 | [diff] [blame] | 163 | send_unreach(skb, ICMP_HOST_ANO); |
YOSHIFUJI Hideaki | e905a9e | 2007-02-09 23:24:47 +0900 | [diff] [blame] | 164 | break; |
| 165 | case IPT_ICMP_ADMIN_PROHIBITED: |
Herbert Xu | 3db05fea | 2007-10-15 00:53:15 -0700 | [diff] [blame] | 166 | send_unreach(skb, ICMP_PKT_FILTERED); |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 167 | break; |
| 168 | case IPT_TCP_RESET: |
Jan Engelhardt | 7eb3558 | 2008-10-08 11:35:19 +0200 | [diff] [blame] | 169 | send_reset(skb, par->hooknum); |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 170 | case IPT_ICMP_ECHOREPLY: |
| 171 | /* Doesn't happen. */ |
| 172 | break; |
| 173 | } |
| 174 | |
| 175 | return NF_DROP; |
| 176 | } |
| 177 | |
Jan Engelhardt | af5d6dc | 2008-10-08 11:35:19 +0200 | [diff] [blame] | 178 | static bool reject_tg_check(const struct xt_tgchk_param *par) |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 179 | { |
Jan Engelhardt | af5d6dc | 2008-10-08 11:35:19 +0200 | [diff] [blame] | 180 | const struct ipt_reject_info *rejinfo = par->targinfo; |
| 181 | const struct ipt_entry *e = par->entryinfo; |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 182 | |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 183 | if (rejinfo->with == IPT_ICMP_ECHOREPLY) { |
Patrick McHardy | 0d53778 | 2007-07-07 22:39:38 -0700 | [diff] [blame] | 184 | printk("ipt_REJECT: ECHOREPLY no longer supported.\n"); |
Jan Engelhardt | e1931b7 | 2007-07-07 22:16:26 -0700 | [diff] [blame] | 185 | return false; |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 186 | } else if (rejinfo->with == IPT_TCP_RESET) { |
| 187 | /* Must specify that it's a TCP packet */ |
Joe Perches | 3666ed1 | 2009-11-23 23:17:06 +0100 | [diff] [blame] | 188 | if (e->ip.proto != IPPROTO_TCP || |
| 189 | (e->ip.invflags & XT_INV_PROTO)) { |
Patrick McHardy | 0d53778 | 2007-07-07 22:39:38 -0700 | [diff] [blame] | 190 | printk("ipt_REJECT: TCP_RESET invalid for non-tcp\n"); |
Jan Engelhardt | e1931b7 | 2007-07-07 22:16:26 -0700 | [diff] [blame] | 191 | return false; |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 192 | } |
| 193 | } |
Jan Engelhardt | e1931b7 | 2007-07-07 22:16:26 -0700 | [diff] [blame] | 194 | return true; |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 195 | } |
| 196 | |
Jan Engelhardt | d3c5ee6 | 2007-12-04 23:24:03 -0800 | [diff] [blame] | 197 | static struct xt_target reject_tg_reg __read_mostly = { |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 198 | .name = "REJECT", |
Jan Engelhardt | ee999d8 | 2008-10-08 11:35:01 +0200 | [diff] [blame] | 199 | .family = NFPROTO_IPV4, |
Jan Engelhardt | d3c5ee6 | 2007-12-04 23:24:03 -0800 | [diff] [blame] | 200 | .target = reject_tg, |
Patrick McHardy | 1d5cd90 | 2006-03-20 18:01:14 -0800 | [diff] [blame] | 201 | .targetsize = sizeof(struct ipt_reject_info), |
| 202 | .table = "filter", |
Patrick McHardy | 6e23ae2 | 2007-11-19 18:53:30 -0800 | [diff] [blame] | 203 | .hooks = (1 << NF_INET_LOCAL_IN) | (1 << NF_INET_FORWARD) | |
| 204 | (1 << NF_INET_LOCAL_OUT), |
Jan Engelhardt | d3c5ee6 | 2007-12-04 23:24:03 -0800 | [diff] [blame] | 205 | .checkentry = reject_tg_check, |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 206 | .me = THIS_MODULE, |
| 207 | }; |
| 208 | |
Jan Engelhardt | d3c5ee6 | 2007-12-04 23:24:03 -0800 | [diff] [blame] | 209 | static int __init reject_tg_init(void) |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 210 | { |
Jan Engelhardt | d3c5ee6 | 2007-12-04 23:24:03 -0800 | [diff] [blame] | 211 | return xt_register_target(&reject_tg_reg); |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 212 | } |
| 213 | |
Jan Engelhardt | d3c5ee6 | 2007-12-04 23:24:03 -0800 | [diff] [blame] | 214 | static void __exit reject_tg_exit(void) |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 215 | { |
Jan Engelhardt | d3c5ee6 | 2007-12-04 23:24:03 -0800 | [diff] [blame] | 216 | xt_unregister_target(&reject_tg_reg); |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 217 | } |
| 218 | |
Jan Engelhardt | d3c5ee6 | 2007-12-04 23:24:03 -0800 | [diff] [blame] | 219 | module_init(reject_tg_init); |
| 220 | module_exit(reject_tg_exit); |